browser-intent

Warn

Audited by Socket on Jul 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and uses an official npm-distributed dependency, but it materially expands risk by combining untrusted web content, external LLM routing, and autonomous browser actions. The documented loopback proxy and graceful degradation are positive signals, so this is not confirmed malware; overall risk is medium due to prompt-injection and action-execution exposure.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Jul 6, 2026, 05:40 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fbrowser-intent%2F@ce7cf02a760b411e9b03d0f04d334f44a6d960d7cc7c98e847a9ba009ef4d52a
Security Audit — socket — browser-intent